menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

Time for Canada to take a fix on defence cybersecurity provisions

6 0
07.08.2026

Mariners call it taking a fix: verifying that a ship remains on its intended course and, if it’s not, adjusting direction accordingly.

On July 13, the U.S. Department of Defense effectively took a fix when it suspended the second phase of its program to protect sensitive unclassified information. The requirements would have introduced mandatory third-party cybersecurity certification across much of the defence industrial base, though some contractors could still self-assess. Instead, the department ordered a 60-day review.

What the department did not suspend matters more. The current cybersecurity standard for defence suppliers remains the baseline; self-assessments remain in force and the obligation to safeguard sensitive defence information remains enforceable. The Pentagon has not paused cybersecurity; it has paused one way of proving it.

For Canada, which has based its own certification program on the American model, that distinction is important.

Cybersecurity is not the same as certification. Cybersecurity is the goal; certification is one way of ensuring it. Treat them as the same and you risk defending the means instead of the goal. The U.S. has paused. Canada should pause, too, before mandatory third-party certification becomes part of Canadian defence contracts.

Costly third-party certification

The U.S. decision did not emerge in isolation. In March, the Government Accountability Office identified a gap in the department’s planning. It had not assessed how it would manage external factors, including whether the private sector has sufficient capacity to assess cybersecurity. The Small Business Administration identified additional challenges, including the cost of third-party certification (priced at roughly US$205,000 per company above the cost of self-assessment). These findings were enough for the Pentagon to pause. Canada should follow that lead.

The Canadian government announced its own cybersecurity program for defence and federal security........

© IRPP - Policy Options